Skip to main content
InterProWebHost InterProWebHost
Site Security

Strong Passwords and Two-Factor Authentication

Most account break-ins do not involve clever hacking. They involve a password that was weak, reused from a breached site, or phished. Two simple habits, strong unique passwords and two-factor authentication, block the overwhelming majority of these attacks. This article shows you how to do both properly across your InterProWebHost accounts.

What makes a password strong

Length beats complexity. A password of 16 or more characters is far harder to crack than a short one with symbols. Better yet, use a passphrase: four or five random words strung together. It is easier to type and harder to break than the typical eight character puzzle. What matters most is uniqueness. The biggest password risk is reuse: when one site leaks its password database, attackers try those same passwords everywhere else. Your hosting, WordPress, and email passwords must each be unique, because a breach anywhere becomes a breach everywhere if they match.

Use a password manager

Nobody can memorize dozens of long unique passwords, and you should not try. A password manager generates strong passwords, stores them securely, and fills them in for you. This removes the temptation to reuse passwords or keep them in a spreadsheet. Pick a reputable password manager, protect it with a strong master passphrase and two-factor authentication, and let it handle the rest. This single change improves your security more than any other habit in this article.

Turn on two-factor authentication everywhere

Two-factor authentication, or 2FA, requires a second proof of identity at login, usually a time based code from an authenticator app on your phone. Even if someone steals your password, they cannot log in without that code. Enable it on every account that offers it, in this order of importance.

  • Your InterProWebHost client area. This controls your services, billing, and access to support. Protect it first.
  • cPanel. cPanel offers two-factor authentication in its security section. This guards your files, databases, and email settings.
  • WordPress admin accounts. Use a well-reviewed two-factor plugin from the WordPress plugin directory. Enable it at least for all administrator accounts.
  • Your email accounts. If your mail provider or app supports a second factor, turn it on. Email access can be used to reset passwords everywhere else.

When you enable 2FA, save the backup or recovery codes somewhere safe, such as your password manager. If you lose your phone without those codes, regaining access is a slow and painful process.

Passwords to change right now

If any of these are true, change the password today: you have used the same password on more than one site, your WordPress admin username is “admin,” you received a breach notification involving an address you use, or someone who should no longer have access once had it, such as a former developer or employee. When someone’s access ends, change shared passwords and remove their user accounts the same day.

If you lose your second factor

Phones get lost and authenticator apps get wiped. That is why every 2FA setup gives you backup or recovery codes: one time codes that get you back in. Store them in your password manager the day you enable 2FA, not after you need them. If you are locked out without codes, you will need to verify your identity through support, which takes time by design. Ten seconds of preparation now saves days of hassle later.

What about the rest of your team?

Your security is only as strong as the weakest login on the team. Make 2FA and unique passwords a policy, not a suggestion, for everyone with access to the website, hosting, or business email. When someone leaves the team, remove their accounts immediately rather than meaning to do it later. Most small business breaches trace back to an old account that should have been closed.

Still stuck? Open a support ticket and tell us which account you are securing. We can confirm 2FA is available on your service and point you to the right settings.

Continue exploring

Site Security

How to Recover a Hacked WordPress Site

Strange new admin users, spammy links appearing in your pages, Google warning visitors away from your site, or emails you never sent going out from your domain: these are the…

3 min read